In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label XXXXX. Show all posts
Showing posts with label XXXXX. Show all posts

Thursday, May 3, 2018

13429 - Aadhaar — A Self Certified ID - Medium.Com




Public availability of cracked Enrollment software makes Aadhaar information equivalent to a Self Certified ID

The biggest question that the Asia Times news story raises about the compromised enrollment software is — Why UIDAI cannot fix it? This post answers this question and the implication of this compromise.




The Offline Problem
The Enrollment Client Multi-Platform (ECMP) software is a JAVA client software available for public download and installation. Instead of a fully online model (Like a Software as a Service hosted only on uidai.gov.in), the client model was chosen because of the lack of reliable internet connectivity in most parts of rural india.

The ECMP software can be used to enroll people in a remote location without the need for internet connectivity. It generates enrollment packets, which are then uploaded to the CIDR for De-duplication. Until that happens, the enrollment packets are stored in the laptop in which the enrollment software is installed.

This design, which optimizes for enrollment, however is a security loophole that has been exploited differently for quite a while and the Asia Times story, above, is only a logical progression of a trend.

Can a client be truly tamper proof?
The steps required to convert any laptop connected with hardware kits the into a fully functional authorized enrollment station are listed below:
Step 4 will only succeed if their Aadhaar ID is associated with the enrollment agency and if their bio-metrics matches with the one stored in the CIDR.

So in effect, the only thing that stands between a valid enrollment station and an illegal one, is the bio-metrics of the operator/supervisor.

The first set of attempts to hijack the ECMP software hence were based on forging the fingerprints via artificial molds (Source).

While these are primitive, a better form of exploit emerged over time. The cracking of the enrollment software itself.

Thick Clients are reversable and patchable.
Analyzing the ECMP software is quite simple and can be accomplished by the following steps:
  • Download the Official software from any of the public locations (AISECT).
  • Install it on any windows laptop.
  • Reverse the Java libraries present in C:\UID Authority of India\Aadhaar Enrolment Client\lib\in.gov.uidai.*.jar, using standard tools like Java Disassembler.
A few things stand out
  • There is no obfuscation. (Face Palm #1)
  • There is code to detect tampering of the software, but the programming in that module is quite poor, and can be tampered/bypassed very easily.
  • All security checks are concentrated in one single module, which also ships with instructions on how to rebuild that module, thus making it very patch friendly. (Multiple repeated face palms)
It is a well known axiom in software engineering that in a client — server architecture, the client can never be trusted to be tamper-proof. However the above defects makes it very easy to tamper the enrollment software and create multiple versions, which patch and bypass various security checks.

Chronology of Security checks and their exploits
  • 2009 — The first few versions of ECMP Software did not even encrypt enrollment packets nor did it have GPS for tracking the enrollment locations. (Source)
  • 2012 — The software shipped with GPS modules and introduced encryption of data packets for the first time with 1024 bit RSA Keys. (Version 2.2).
  • April 2012 — The ILF&S scam happened because the enrollment software allowed anyone to use their own fingerprint to become an Aadhaar operator using a vulnerability (Source).
The system has a flaw. When an agent provides wrong authorisation fingerprint, it rejects on two occasions, but at the third instance it automatically takes the default authorisation print and completes the enrollment process,
  • Feb, 8 2016 — First sightings of unauthorized Aadhaar enrollment centers, possibly using a cracked ECMP software (Source)
  • May 2016 — Version 3.2.0.0 shipped with IRIS authentication for the operators, since artificial fingerprints have become mainstream.
  • May 2017 — UIDAI releases Version 3.3.3.0 which contains code to detect tampering of the enrollment software.
  • August 2017 — UP Aadhaar hack case, which reported that IRIS authentication has been bypassed. (See FIR copies here).
  • Feb 2018 — IRIS authentication still remains bypassed, GPS has been bypassed, but Artificial fingerprints are in use (Chandigarh FIR)
  • April 2018 — GPS and Fingerprint checks bypassed (Asia Times story)
Conclusion
The implication of the above is quite clear — The quality of demographic data in the Aadhaar database (CIDR) is whatever the enrollment operators want them to be and residents can directly influence the operators, by paying them a bribe.

The only defense had always been bio-metric de-duplication, but as the UP Aadhaar case indicated, bio-metrics can be injected by operators.


Sunday, April 29, 2018

13400 - Beware, SIM card sellers can misuse your Aadhaar biometrics - The Hindu


HYDERABAD, APRIL 28, 2018 23:37 IST


Thumb rule: Linking of Aadhaar card being done for a new SIM card.   | Photo Credit: G_RAMAKRISHNA

New cards can be activated using fingerprints multiple times
Next time you want to buy a new Subscriber Identity Module (SIM) card for your mobile device, be wary if your retailer tries to take your Aadhaar-linked fingerprints more than once.

The retailer can get a new SIM card activated — without your knowledge — using your thumb impression multiple times. Cases have surfaced of SIM cards thus activated being sold to persons who have then used them to commit crimes.

A SIM card retailer of Yasin Mobiles shop, Mohammed Rahmatullah, in Amberpet of Hyderabad was caught by Department of Telecommunications officials here two days ago on such a charge. “He admitted to have sold over 150 SIM cards fraudulently acquired in this manner. Some of these cards are being used to operate illegal Voice over Internet Protocol (VoIP) phone call rackets at different places in the country,” a senior DoT officer told The Hindu.

VoIP racket
A Hyderabadi woman grew suspicious when she got a phone call from abroad with a local mobile phone number. She complained to a DoT call centre. “Our inquiries confirmed that she got phone call from abroad through someone operating a VoIP racket, who purchased a local SIM card from a retailer. The latter got that SIM card activated by misusing Aadhaar biometrics of an unsuspecting person,” they explained. 

Further investigations suggested that SIM cards obtained by misusing customers were being used by many illegal phone call operators in other parts like Delhi. “We’re alerting officials concerned and catching them with the help of local police,” the DoT officials said. VoIP call rackets are not only making a huge dent on the exchequer but also raising security concerns. The authorities are worried that these cards may land in the hands of terrorists.

Mobile phone service SIM card sellers have Aadhaar card biometrics readers, and the scanners are connected to a computer to process applications for different service providers. Retailers verify customer’s fingerprints often with customers not being able to see the confirmation of identify on computer screens.

“Customers do not know if biometrics matched in the first attempt. Hence, retailers collect fingerprints multiple times,” the authorities said. When the fingerprints match, automatically all details, including photograph, available in Aadhaar card, are captured in the mobile phone service provider’s Know Your Customer (KYC) form.

Earlier, this was done manually using a photocopy of customer’s identity proof document. The retailers who create multiple SIM using a single identity are reportedly selling them to fraudsters for ₹1,000 to ₹3,000 each.

Since roaming charges were done away with, SIM cards purchased in Hyderabad can be used anywhere. “Our analysis of some SIM cards sold by Rahmathullah suggest that they were being used to operate VoIP call rackets from various places in the country,” the investigators said.

Amberpet police of Hyderabad Commissionerate registered a criminal case against Mohammed Rahamatullah and he was booked under sections 471 (using forged document or electronic record as genuine) and 420 (cheating) of IPC, besides Indian Telegraph Act provisions.

DoT officials are planning to take up a countrywide campaign to caution people against falling prey to the misuse of Aadhaar biometrics by SIM card sellers. Mobile phone service providers have been asked to send individual messages to all their customers about the fraudulent practice.


The campaign would use short video clips, slides and photos. “We are yet to devise a plan on alerting people of rural and remote parts about the scam,” the officials said.

Saturday, April 21, 2018

13329 - Aadhaar is operationally different from smart cards and Google, which presents them with little incentive to work against UIDAI - First Post

News-Analysis Nimish Sawant Apr 19, 2018 18:25 PM IST

In the on-going Aadhaar Supreme Court hearings, senior counsel Rakesh Dwivedi was alleged to have made a statement to the extent that Google and smart card companies had created a lobby against Aadhaar.

Later in the day, UIDAI sent out a series of tweets stating that Dwivedi's arguments that Google is trying to fail Aadhaar were not correct.

It is clarified that the media reports which were published today quoting UIDAI’s Counsel Shri Rakesh Dwivedi’s argument yesterday in the Supreme Court that Google is trying to fail Aadhaar, are not correct. 1/n


Shri Rakesh Dwivedi, Senior Advocate had submitted that as far as Google, Facebook and Twitter are concerned, they cannot be compared with Aadhaar due to the nature of information being different and also due to difference in the nature of algorithms being used. 2/n

Lawyers and witnesses present in the court state otherwise and this is open to debate.

Dwivedi also clarified that the Aadhaar data is not available on the internet, from where it can be stolen. We'd like to point out that it's not clear whether he's talking about biometric data or demographic data. Multiple leaks in the past, especially from government entities, has resulted in the leak of demographic data (name, address, contact details, etc.) of several thousand Indians, if not millions of Indians.

While UIDAI has stated that there is no attempt by Google to fail Aadhaar, the question of a Google lobby seems moot. But smart cards are a means of identification in many nations, and while in India a lot of the petitioners have expressed an interest to have a smart card in case of an Aadhaar number for verification and authentication purposes, it has so far remained just an idea.

A woman goes through the process of finger scanning for the Unique Identification (UID) database system, also known as Aadhaar. Image: Reuters

Smart Cards as a national ID 
A smart card is like any other debit or credit card, made of plastic with embedded chips which could be RFID compatible. The chips in these smart cards house the personal data of the user, which can only be read by an authorised authenticating machine. A lot of countries use smart cards as a national identification tool. These include Brazil, Israel, Malaysia, Estonia, Indonesia, among others. You can read a detailed comparison of how Aadhaar compares with other biometric national identification systems around the world.

While there was no clarification of what was meant by a 'smart card lobby', it was reported that the UIDAI felt like 'a campaign had been unleashed to ensure Aadhaar should be a smart card, 'a European based commercial venture'. Since UIDAI has distanced itself from this, we will not get into the semantics of it, as this is as vague a statement as any.

Smart cards, specifically in Europe are quite popular. Estonia has been the leader when it comes to smooth implementation of smart cards and their use in governmental as well as non-governmental services.

Smart ID is an Estonian company which allows you to find out the real identity of users. "Smart ID has implemented many different identification methods to identify people because each country has its own popular methods and this list just keeps on growing. Currently, it is possible to identify people securely in Estonia, Latvia, Lithuania and Portugal. Each method has its own security level. National ID cards with smart cards are considered one of the most secure," says its website.

Here is a list of all the national smart ID cards in use in various European nations. Norway, Denmark, Iceland, the UK are some exceptions, however. Each country has its own rules, whether to make a national ID card compulsory or optional for authentication and services. In an exceptional case, the UK even destroyed its ID card system.

On days 8 and 9 of the Aadhaar Supreme Court hearings, petitioners drew the attention of the Bench to Israel’s smart ID system, where users could use the card to avail benefits and services if they wished to do so. The system used biometric authentication and has a database, but the database lacks any identifying information. In summary, the petitioners argued that there can be an ID card, but it must be voluntary, authentication data must be on the card, it should not collect data, and the people should have the right to alternatives.
According to experts we have spoken to, making Aadhaar a national smart card would take quite a while and would involve a lot of logistics. But the allegation of a smart card lobby sounds like speculation at best, without any proof being presented as to which are the parties that may be interested in this.

Estonia has one of the most advanced Smart ID Card systems. Image: Wikipedia

Google has little incentive to lobby against Aadhaar
Unlike Aadhaar, Google is a private company and provides services to users for which there are alternatives. If I want to use Google services, I have to make an ID on Google and as I use more Google services, it gets to know me better. I have to opt-in for Google Assistant as it gives me an experience which adds value to my online journey. If I decide that I don't want to associate with Google services, I can do a 'Google Takeout' ie. take a backup of all my data, delete my Google accounts and opt-in for any other alternative service for mail, search, video viewing and so on.

Bottomline — as a user, I have an option to choose if I want to remain with Google.

With Aadhaar becoming a national ID and one that is intricately linked to so many services, there is no option for me to opt out if I don't want to share my Aadhaar details with services which mandate it.

As rightly pointed out by the UIDAI counsel, unlike Aadhaar, Google uses machine learning algorithms to learn more about me. Well, Google is a technology company first, and its use of machine learning and AI should not come as a surprise. This is done to give users an online experience that is catered to their habits and personas. There is an incentive for companies such as Google, Facebook and others to use machine learning and artificial intelligence in their services. Of course, there is scope for misuse too, as we have all seen with the Facebook Cambridge Analytica scandal.

Aadhaar, on the other hand, is primarily meant to be used to authenticate you, as you. UIDAI has also stated that not every private entity will be given access to Aadhaar authentication machines. This same private entity can ask you to register or login using your Google ID to access its services. So there again, is a big difference in how these systems work.
When you look at the differing use cases that each of these services such as Aadhaar, smart cards and Google provide, one thing that emerges is that there is no real motivation for a 'Google and Smart card lobby' to work against Aadhaar.
The UIDAI distancing itself from these statements is an added validation of how it may have been a slip of tongue.


Updated Date: Apr 19, 2018 18:25 PM

13328 - Not sure if Aadhaar is best model to accord benefits, Supreme Court says - Times of India


PTI | Updated: Apr 19, 2018, 21:57 IST

HIGHLIGHTS
  • The counsel for UIDAI told SC that Aadhaar brought the citizens face to face with the service providers
  • "The individual should not be a supplicant. The state should go to him and give him benefits," the bench responded

NEW DELHI: The Supreme Court on Thursday said it was not sure whether bringing people "face to face" with authorities through Aadhaar was the best model as the state should reach them to accord the benefits of the welfare schemes. 

A five-judge Constitution bench headed by Chief Justice Dipak Misra, hearing a clutch of petitions challenging Aadhaar and its enabling 2016 law, was told by the counsel for the Unique Identification Authority of India (UIDAI) that the 12-digit national identifier brought the citizens face to face with the service providers for getting the benefits. 

"We are not sure if that is the best model. The individual should not be a supplicant. The state should go to him and give him benefits," the bench, also comprising Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan, said. 

The bench observed that the UIDAI says Aadhaar is a means for identification, but the "only caveat to that is that there should be no exclusion". 

Senior advocate Rakesh Dwivedi, appearing for UIDAI and the Gujarat government, said the development was necessary to ensure that people are freed from poverty. 

Liberating people from poverty is at one end of the spectrum and the right to privacy is on the other, the bench observed. 

The UIDAI referred to social ills like manual scavenging and prostitution and said that despite laws, these evils were rampant in the society and the apex court should strike a balance while dealing with the competing fundamental rights of citizens. 

Referring to apex court judgements, the senior lawyer said it has been held that to save the freedom of speech and expression, the right to reputation of a citizen under Article 21 cannot be crucified. 

The apex court, besides being the protector of fundamental rights, is also a "balancing wheel" to ensure that competing fundamentals co-exist. 


Dwivedi then referred to a verdict by which a HIV+ve rape victim was denied the permission to abort the foetus after a doctors' panel gave the report that it could be fatal for the woman. 

Thursday, April 19, 2018

13308 - SC red flags threat of Aadhaar data misuse, asks searching questions - TNN


PTI | Updated: Apr 17, 2018, 23:01 IST

HIGHLIGHTS
  • The SC bench referred to the Cambridge Analytica controversy and said these are not "imaginary apprehensions"
  • In the absence of robust data protection law, the issue of misuse of information becomes relevant: SC
  • Bench asked UIDAI counsel why authorities were allowing private entities to use the Aadhaar platform

NEW DELHI: The Cambridge Analytica data leak controversy today found mention in the Supreme Court, which red flagged the threat of probable misuse of citizens' information by entities which were getting Aadhaar details authenticated by the UIDAI

A five-judge constitution bench headed by Chief Justice Dipak Misra, hearing clutch of petitions challenging Aadhaar and enabling 2016 law, referred to the Cambridge Analytica controversy and said these are not "imaginary apprehensions" and, in the absence of robust data protection law, the issue of misuse of information becomes relevant. 

"The real apprehension is that elections are swayed using data analytics. These problems are symptomatic of the world we live in," the bench, also comprising Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan, said. 

"Please do not bring Cambridge Analytica into this. The UIDAI simply does not have the learning algorithms like Facebook, Google to analyse details of users," senior advocate Rakesh Dwivedi, appearing for Unique Identification Authority of India (UIDAI) and the Gujarat government, said. 

Besides the Aadhaar Act does not authorise any kind of data analysis, he said, adding the UIDAI has "simple matching algorithms" which give answers like 'yes' or 'no' after it receives a request for Aadhaar authentication from a requesting entity. 

The bench, which posed several searching questions, asked the lawyer why the authorities were allowing private entities to use the Aadhaar platform for various purposes and referred to the legal provision to this effect. 

"Why are words 'body corporate or any person' used in section 57 of the Act. It breaks the nexus of the Act with the Consolidated Fund of India... What is the point of involving private parties in the Aadhaar infrastructure," the bench asked. 

Dwivedi responded by saying that "it does not allow any 'chaiwala' or a 'panwala' to become a requesting entity under the Act. It is a limited exercise. The UIDAI will not approve anyone to become an requesting entity (RE) unless it is satisfied that the particular entity needs to use facility of authentication." 

He also referred to private companies like Reliance venturing into the defence sector and said at some point in time, the court will have to decide the aspect where private firms were dealing with public functions of the state, which are currently being carried out by public sector companies. 

He also urged the bench not to give in to the "hyper phobia" against the Aadhaar created by the petitioners opposed to the "inclusive scheme" of the government based on a law and the proper infrastructure. 

"Lobbies favouring smart cards do not want this scheme to succeed as they are opposed to Aadhaar," the senior lawyer said, adding there have been efforts from many quarters to ensure that this scheme, which is more secure and works offline, does not work. 

The bench then referred to the provisions of the Aadhaar Act and said the misuse of information at the end of UIDAI may not happen, but there could be possibility of misuse or commercial abuse of information by private entities involved in Aadhaar authentication. 

To this, the lawyer said the Aadhaar Act provided enough data protection to citizens and contained provisions to punish the offenders for any breach and moreover, the core biometric details cannot be shared by UIDAI. 

"No data protection law can provide hundred percent protection. The test should be 'reasonable, fair and just'," he said, adding that "aggregation, analysis or transfer of data" is not allowed under the statute. 

The lawyer also referred to uncertainties faced in life and said nothing was 100 per cent secure as people died in air travel and accidents on the highways. 

He then referred to the fact that documents like passport, PNR and boarding passes of airlines contain numbers only and it does not mean that identity of an individual is lost. 

He said biometric details do not contain genetic data and they are not intrusive and they are used in instant digital authentication of Aadhaar holder. 

"Aadhaar is not just an exercise to provide benefits and weed out fakes but also to bring the service providers face to face with the beneficiaries. That is the revolutionary aspect of Aadhaar," he said.


"Aadhaar is not the panacea for all evils but the problems that were occuring on account of fake identity documents will be solved," he said.

The bench took note of the plea that Aadhaar cannot be struck down solely on the ground that it is "probabilistic".

However, it said, "If probability leads to deprivation of fundamental rights, then there should be safeguards in place to ensure that this deprivation does not happen. There should be an administrative machinery in place to ensure no genuine beneficiary is deprived."

The advancing of arguments remained inconclusive and would resume tomorrow. 


Monday, April 9, 2018

13233 - Myth busted - Editorial - Statesman

Editorial | April 8, 2018 1:14 am
SC AADHAAR


The Constitutional validity of the Aadhaar scheme is yet to be judicially determined, but without opining on that key issue the apex court has ridiculed the concerted effort of government agencies to project the Aadhaar card as a magic wand, capable of blowing away many of the myriad complications in providing effective governance.

In a series of observations on Friday, members of the five-member Constitutional bench had the courtroom chuckling when they “quizzed” the Attorney-General on the various claims being made that an Aadhaar card would end bank frauds, counter-terrorism and what have you.

Clearly impacted by the revelations of data leaks by Facebook and Cambridge Analytica, the court indicated it did not buy the official sales-pitch, and virtually cautioned the government against exaggerating the virtues of the new-found replacement for a ration card, passport, or official identity-document. Food for thought, provided the government concedes the need for “thinking”.

The trigger for the barrage he faced was provided by the government’s top law officer when he said Aadhaar cards would prevent bank frauds. Their Lordships countered “a bank fraud does not take place because of multiple identities. A loan is given by a banker and he knows who the borrower is.
A fraud can take place if the banker is hand in glove with the customer… Aadhaar can do little to stop it”. And one member of the Bench proceeded to assert that “to stop bank frauds the manager or officials at that level need to carry out due diligence before advancing loans.”

Dealing with the contention that the card was an anti-terrorism tool, the court said, “we are not questioning the political wisdom to suspend internet…. But do terrorists apply for a telephone? They communicate through cell phones, satellite phones but they don’t apply for phones, so is it really necessary to ask all to give Aadhaar for taking telephones?”

Their Lordships clarified that “Aadhaar does not become unconstitutional just because it cannot address all problems. Use of Aadhaar to uplift those as the bottom of the pyramid is welcome. The targeted persons must get financial benefits, and corrupt means need to be stopped.

Problem is how far can the net be cast? Aadhaar may not be objectionable, but linking it to every activity is…” When the Attorney General argued that those who received the various benefits extended under the Aadhaar umbrella had no right to complain about violation of their right to privacy, the court slammed that as a “Marxist argument”.


Those were firm indications of their Lordships’ train of thinking…. all that even before they dealt with the political argument that the Aadhaar legislation was declared a “money bill” only to deny the Rajya Sabha opportunity to debate/reject it. The Aadhaar debate, like so much else on the national table, is clearly “hotting up”.

13229 - Ex-Law Min Shanti Bhushan Files PIL Alleging Abuse of Power - The Quint

https://www.thequint.com/news/india/shanti-bhushan-cji-dipak-misra-abuse-of-power-master-of-roster

Ex-Law Min Shanti Bhushan Files PIL Alleging Abuse of Power by CJI

Even as the Congress confirmed that it would not be bringing an impeachment motion against Chief Justice of India Dipak Misra, the Supreme Court is faced with a new controversy. Former Law Minister and veteran advocate Shanti Bhushan has filed a PIL before the apex court challenging the CJI’s power as ‘Master of the Roster’, in which he has alleged “gross abuse of powers” in relation to listing cases.
In November 2017, a Constitution Bench headed by CJI Misra had passed a judgment clarifying that the CJI alone had the power to decide which judges of the Supreme Court heard which case – as part of his/her prerogative as ‘Master of the Roster’. The judgment was controversial since it held that even if a case involved allegations of corruption or bribery against the CJI, he/she would still be the one to decide which judges to assign the case to.
Bhushan’s PIL seeks to check this “unguided and unbridled discretionary power”. According to the petition, this power has been exercised by the CJI and the Supreme Court’s Registry in a way that demonstrates “a pattern of favouritism, nepotism and forum shopping”, which threatens the independence of the judiciary, and therefore needs to be reviewed.

Gross Abuse of Powers

Bhushan submits that the CJI has used his power to list matters of general public importance and/or of political sensitivity before certain benches of the court only, which reflects, according to him, a gross abuse of the CJI’s powers and a negation of the Rule of Law.
The petition lists ten examples of such abuse, which relate to some of the biggest national controversies in recent months. These include:
The Judge Loya Death Investigation Case
Bhushan notes that the case was “surprisingly” ordered to be listed before Court No 10 of the Supreme Court, headed by Justice Arun Mishra. After this was specifically noted as a matter of concern during the press conference by the four senior judges of the court on 12 January, the bench eventually ordered that the matter be listed before an “appropriate Bench as per roster”.
However, there was no detailed roster in existence at the time, and eventually the matter was taken up in the court of the CJI himself.
The CJAR Medical Bribery Petition
This was the matter which led to the CJI’s ‘Master of the Roster’ judgment. A petition by the Campaign for Judicial Accountability and Reforms was mentioned urgently in November 2017 before Court No 2, headed by Justice Chelameswar. Though mentionings are normally supposed to take place in the CJI’s court, this petition was filed in Justice Chelameswar’s court as the CJI was presiding over a Constitution Bench hearing the Delhi vs Centre case, and the petition itself involved potential allegations against the CJI.
The CJI had the matter taken away from Justice Chelameswar’s court, and asserting his power as ‘Master of the Roster’, referred it to a separate bench of Justices RK Agrawal, Arun Mishra and AM Khanwilkar. This bench went on to dismiss the petition in December 2017, and imposed costs of Rs 25 lakh against the petitioners.
The Centre for Public Interest Litigation’s 2G Case
Another matter listed before Justice Chelameswar’s court in November 2017, another matter taken away and placed before the CJI himself. After the two judges sitting with the CJI recused themselves, the matter was then placed before a bench presided over by Justice Arun Mishra.
Bhushan notes that this was done “even though other Benches of senior Hon’ble Judges were available.”
The Aadhaar Case
Bhushan’s petition points out that the Aadhaar case was originally heard by a bench including Justices Chelameswar and Bobde back in 2015, who had referred it to a higher bench to decide the issue of right to privacy. Both these judges were part of the 9-judge bench that held that privacy is a fundamental right in August 2017.
However, Bhushan points out that both have been excluded from the Constitution Bench deciding on the validity of Aadhaar, which was set up by CJI Misra.
The Land Acquisition Per Incuriam Judgments Controversy
In February 2018, a 3-judge bench headed by Justice Arun Mishra held a 2014 decision about land acquisition law by another 3-judge bench to be incorrect – something which most legal experts believed should not have been possible. Justice Lokur, who had been part of the 2014 decision, passed an order requesting the courts not to make any decisions about this issue until his bench, which was hearing another land acquisition matter, decided whether a larger bench was needed to resolve the conflict.
Despite this, multiple land acquisition matters dealing with this issue were listed before Justice Mishra’s bench, and he passed orders in these before the CJI finally decided to list the matter before a higher bench – headed by him.

Need for Review of Procedures

Bhushan argues that vesting so much power in the CJI’s hands is contrary to the Constitution, the Supreme Court’s Rules and Handbook, and the values that the judiciary is supposed to espouse.
As a result, the petition asks for the following:
  1. That listing of Supreme Court cases be strictly on the basis of the Supreme Court Rules 2013 and the Handbook on Practice and Procedure and Office Procedure;
  2. That in interpreting the Rules and Handbook, the powers vested in the CJI should be construed as lying with not just the CJI but a collegium of 5 senior judges of the Supreme Court.
  3. That the CJI be prevented from listing matters in a different manner from that specified in the Rules and Handbook.
Since the PIL lists the CJI as one of the parties to the case, Bhushan’s covering letter argues that the case should not be heard by a bench which includes him. This touches on another issue raised against CJI Misra – that his new system of assignment of cases has ensured that all PILs are to be heard by his courtroom only. As a result, Bhushan has asked that the next three senior-most judges of the court should decide how to proceed with the petition.
You can read the whole petition here:

Saturday, April 7, 2018

13213 - Constitutional Validity of Aadhaar, Day 25: "Proportionality is Key" - Medianama

Constitutional Validity of Aadhaar, Day 25: "Proportionality is Key"
Vidyut


By Vidyut ( @Vidyut vidyut@medianama.com ) April 6, 2018
Share This: Share via Email

This is a record of the proceedings in the Supreme Court bench hearings on the Constitutional validity of Aadhaar, which began on Feb 13, 2018. You may read the previous days’ proceedings here: Day 1, Day 2, Day 3, Day 4, Day 5, Day 6, Day 7, Day 8, Day 9, Day 10, Day 11, Day 12, Day 13, Day 14, Day 15, Day 16., Day 17, Day 18, Day 19, Day 20, Day 2, Day 22, Day 23 and Day 24.

The Attorney General continued his arguments, reading from his submissions about the US Court of Appeals case (page 261) on DNA storage of arrested persons (MediaNama: All further reading is from this document unless linked separately).

The CJI cautioned AG that this does not apply in this case as it is narrowly deals with offenders. The AG said he wanted to read the portion relating to retention of DNA. Teh CJI allowed him to continue reading. “…Court shall not base its reasoning on Hollywood fantasies…”

Justice Chandrachud said that this does not arise in our case. He reiterated that the problem with Aadhaar is that the administrative authority can define section 2(g) of the Act. This might not meet the test of proportionality.
The AG said he will meet that point. He paraphrased it as an excessive delegation point.(Prasanna: No no no there are two distinct points. An independent stand-alone excessive delegation point and an independent proportionality-privacy relatable excessive delegation point.)

The AG next read a Fordham Law Journal article on how automated finger imaging does not violate privacy. He emphasized the part in the article that asserts that finger imaging technology is 99.9% accurate. He submitted that biometrics is a very safe and accurate technology and said biometrics can problems such as money laundering, bank frauds, income tax evasion etc.

AG said watching television every day is shocking…crime on the rise every day. Bank frauds totalling lakhs of crores. This will catch them all. Justice Sikri laughingly said Bank frauds have got nothing to do with this – bank frauds weren’t caused because of multiple identities. The AG responded by citing benamis multiple identity based frauds.
Justice Chandrachud also joined Justice Sikri and said nothing in Aadhaar prevents an individual operating a layer of commercial entities to do a chain of transactions. He said he didn’t see how Aadhaar is going to help with detecting or preventing bank frauds. It can only help in providing benefits under section 7 at most.

Justice Chandrachud said that mere legitimate state interest does not ensure proportionality. He said that the AG’s submission lacks this nuance.

The AG said that Aadhaar will help in income disparity and eliminating poverty. Justice Sikri said that the gap is widening – inequality is increasing. More than 70% wealth is in the hands of 1%. No question of India having bridged inequalities. Some debate ensued on Trickle down economics (AG referred to Gurucharan Das) and Justice Sikri referring to Prof Amartya Sen.

Justice Chandrachud said that the legitimacy of the interests involved here is a given, but the crux lies in proportionality. Proportionality is key. How far can the state cast a net of Aadhaar? Only section 7 seems to be understandable.

Justice Sikri said that the State cannot assume that the entire population consists of defaulters and violaters. What is the logic in linking all sim cards to aadhaar.
The AG said that terrorism will be curbed by doing this.
Justice Sikri took the example of mobile-Aadhaar linking. He asked where the proportionality in suspecting everyone to be a terrorist is. The AG responded with the example of Kashmir and said they shutdown internet to ensure stone throwers don’t communicate with each other and assemble. (MediaNama: Even arguing that such censorship were to be justified, how would shutting down the internet in an entire area be improved by knowing the Aadhaars of those whose internet was shut?)

Justice Chandrachud asked whether terrorists apply for a cell phone? They may use, but do they apply? He said that it’s a problem that the State is asking the entire population to link their mobile phones with Aadhaar.

The AG said that we are asking for minimal information via Aadhaar. He said that most information is already available in public domain. He said that the question is to what extent has Aadhaar invaded privacy? He claimed it’s as minimum as possible.

The Bench rose for lunch and reassembled at 2.30 pm.

The AG resumed his submissions. He said Aadhaar is required only for section 7 benefits, banks, income tax and mobile nos. Apart from that it’s purely voluntary. Emphasized that linking Aadhaar with mobile number will help in curbing terrorism. He said that the Court needs to balance two competing rights and maintained that right to food, right to employment, right to medical care, etc trump right to privacy. Can right to privacy be invoked to deprive other sections of the society, he asked.

The AG repeated that the invasion to privacy is so minimal that it can’t even be considered an invasion. He cited X v. Hospital Z wherein right to privacy was balanced against right to information. The appellant ( a man) had HIV and had the right to non disclosure. However, the court had held that his fiance had the right to know of his disease.

Justice Sikri said that this is the case of balancing the rights of two person. In the case of Aadhaar, the State is giving a person food in exchange of their privacy.

The AG said that the bare minimal requirements for identification for an individual is alone taken and to the extent that the technology permitted. Should people have basic right to life under article 21? Can it ever be challenged on the ground that we have a right to privacy, he asked.

Justice Bhushan remarked that minimal invasion is subjective. The AG asked the bench to look at the information taken and look at it from objective standards. “We have to look at the larger interest of the country.”
Justice Chandrachud said they have to look at three things: informed consent, purpose limitation, and enough security.

The AG said that the CIDR is completely safe.

Justice Chandrachud said that they have to look at what proportionality means. Proportionality hasn’t been defined in the Puttaswamy judgement.
The AG said that without the minimal information that is collected, the entire architecture of Aadhaar couldn’t have been framed. He said sections 29 a and b contain purpose limitation. He cited a few cases on balancing of fundamental rights.

The AG repeated that Aadhaar was voluntary when it was rolled out, therefore there’s no question of violation of any right. He said informed consent was implied. (MediaNama: Actually, Dr. Pandey had said in an interview then that consent was not required.)

Justice Sikri asked if it is permissible to say that I’ll give you food, shelter, etc but you’ll be my slave.

The AG replied that slavery is not permissible.

Justice Chandrachud said that his argument to save the validity of the Act does not take into account what happened before the Act was passed. There was no protection for the citizens that time. He said that there’s no retrospective effect also and asked about collection of data by state governments.

The AG said that state governments act as the agent of the central government.

Senior Counsel Rakesh Dwivedi said that proof of concept study was conducted in rural areas before Aadhaar was decided upon. He said IT act after 2009 empowered the use of Aadhaar for the purpose of e-commerce.

Justice Khanwilkar asked whether biometrics locking option is available for people who don’t want to use Aadhaar.

Mr. Divan interjected and said that there’s no way to opt out of the Aadhaar system.

The Court rose for the day. The Advocate General will continue submissions on behalf of the government at 11:30am on the 10th April 2018.

Summary of hearing based on tweets by Prasanna S, Gautam Bhatia and SFLC.